Server-Side Request Forgery (SSRF) in kalcaddle/kodexplorer
Valid
Reported on
Jun 30th 2021
✍️ Description
The path is vulnerable to ssrf via svg file upload
🕵️♂️ Proof of Concept
upload an SVG file with SSRF payload in it. open option on the file and open with browser.
💥 Impact
redirect host via ssrf
Occurrences
We have contacted a member of the
kalcaddle/kodexplorer
team and are waiting to hear back
2 years ago
allow http on server; such as download a file from same server.
to join this conversation